Trezor says attackers breached its third-party email provider and used that access to send phishing emails to customers from a legitimate Trezor address. The fake messages claimed a made-up STM32 hardware vulnerability could expose wallet recovery seeds and urged users to click through. Trezor says it took the malicious domain offline and is investigating how attackers gained access to its legitimate email-sending setup.
Why it matters: Trezor users face a high-risk phishing threat because the messages appeared to come from a real company address and targeted people who hold cryptocurrency. Customers should avoid links in recent Trezor security emails, verify messages through official channels, and never share wallet seed phrases.
Sergiu Gatlan
2026.09.10
100% relevant
This article establishes a distinct new incident: a breach of Trezor's third-party email provider that enabled phishing from a legitimate Trezor address, separate from the previously tracked ShipMonk customer-data breach.
← Back to all stories